NukeViet kayıtları
nukeviet üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %53,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-502 Deserialization of Untrusted Data2
- CWE-707 Improper Neutralization1
- CWE-918 Server-Side Request Forgery (SSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-7725İstismar yok | includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serializatnukeviet · nukeviet · CWE-502 | Kritik9,8 | — | %2,6 | 31 Ara 2020 |
40Planlayın | CVE-2019-7726İstismar yok | modules/banners/funcs/click.php in NukeViet before 4.3.04 has a SQL INSERT statement with raw header data from an HTTP request (e.g., Referenukeviet · nukeviet · CWE-89 | Kritik9,8 | — | %2,3 | 31 Ara 2020 |
39İzleyin | CVE-2020-21808İstismar yok | SQL Injection vulnerability in NukeViet CMS 4.0.10 - 4.3.07 via:the topicsid parameter in modules/news/admin/addtotopics.php.nukeviet · nukeviet · CWE-89 | Kritik9,8 | — | %1,6 | 30 Tem 2021 |
39İzleyin | CVE-2020-21809İstismar yok | SQL Injection vulnerability in NukeViet CMS module Shops 4.0.29 and 4.3 via the (1) listid parameter in detail.php and the (2) group_price onukeviet · nukeviet · CWE-89 | Kritik9,8 | — | %1,6 | 30 Tem 2021 |
35İzleyin | CVE-2024-36528İstismar yok | nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /adnukeviet · egovernment · CWE-502 | Yüksek8,8 | — | %0,8 | 10 Haz 2024 |
35İzleyin | CVE-2020-13155İstismar yok | clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=clnukeviet · nukeviet · CWE-352 | Yüksek8,8 | — | %0,7 | 23 Haz 2020 |
26İzleyin | CVE-2020-13157İstismar yok | modules\users\admin\edit.php in NukeViet 4.4 allows CSRF to change a user's password via an admin/index.php?nv=users&op=edit&userid= URI.nukeviet · nukeviet · CWE-352 | Orta6,5 | — | %0,6 | 23 Haz 2020 |
26İzleyin | CVE-2020-13156İstismar yok | modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=user_add URI.nukeviet · nukeviet · CWE-352 | Orta6,5 | — | %0,6 | 23 Haz 2020 |
24İzleyin | CVE-2020-22765İstismar yok | Cross Site Scripting (XSS) vulnerability in NukeViet cms 4.4.0 via the editor in the News module.nukeviet · nukeviet · CWE-79 | Orta6,1 | — | %0,6 | 30 Tem 2021 |
24İzleyin | CVE-2022-3975İstismar yok | NukeViet CMS Data URL Request.php filterAttr cross site scriptingnukeviet · nukeviet · CWE-707 | Orta6,1 | — | %0,5 | 13 Kas 2022 |
22İzleyin | CVE-2024-36531İstismar yok | nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.nukeviet · egovernment · CWE-94 | Orta5,7 | — | %0,4 | 10 Haz 2024 |
21İzleyin | CVE-2022-30874İstismar yok | There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02.nukeviet · nukeviet · CWE-79 | Orta5,4 | — | %0,8 | 21 Haz 2022 |
8İzleyin | CVE-2025-8772İstismar yok | Vinades NukeViet Module index.php server-side request forgerynukeviet · nukeviet · CWE-918 | Düşük2,1 | — | %0,5 | 9 Ağu 2025 |
- CVE-2019-772540Planlayın
includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serializat
KritikCVSS 9,8İstismar yokEPSS %3nukeviet · nukeviet31 Ara 2020
- CVE-2019-772640Planlayın
modules/banners/funcs/click.php in NukeViet before 4.3.04 has a SQL INSERT statement with raw header data from an HTTP request (e.g., Refere
KritikCVSS 9,8İstismar yokEPSS %2nukeviet · nukeviet31 Ara 2020
- CVE-2020-2180839İzleyin
SQL Injection vulnerability in NukeViet CMS 4.0.10 - 4.3.07 via:the topicsid parameter in modules/news/admin/addtotopics.php.
KritikCVSS 9,8İstismar yokEPSS %2nukeviet · nukeviet30 Tem 2021
- CVE-2020-2180939İzleyin
SQL Injection vulnerability in NukeViet CMS module Shops 4.0.29 and 4.3 via the (1) listid parameter in detail.php and the (2) group_price o
KritikCVSS 9,8İstismar yokEPSS %2nukeviet · nukeviet30 Tem 2021
- CVE-2024-3652835İzleyin
nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /ad
YüksekCVSS 8,8İstismar yokEPSS %1nukeviet · egovernment10 Haz 2024
- CVE-2020-1315535İzleyin
clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=cl
YüksekCVSS 8,8İstismar yokEPSS %1nukeviet · nukeviet23 Haz 2020
- CVE-2020-1315726İzleyin
modules\users\admin\edit.php in NukeViet 4.4 allows CSRF to change a user's password via an admin/index.php?nv=users&op=edit&userid= URI.
OrtaCVSS 6,5İstismar yokEPSS %1nukeviet · nukeviet23 Haz 2020
- CVE-2020-1315626İzleyin
modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=user_add URI.
OrtaCVSS 6,5İstismar yokEPSS %1nukeviet · nukeviet23 Haz 2020
- CVE-2020-2276524İzleyin
Cross Site Scripting (XSS) vulnerability in NukeViet cms 4.4.0 via the editor in the News module.
OrtaCVSS 6,1İstismar yokEPSS %1nukeviet · nukeviet30 Tem 2021
- CVE-2022-397524İzleyin
NukeViet CMS Data URL Request.php filterAttr cross site scripting
OrtaCVSS 6,1İstismar yokEPSS %1nukeviet · nukeviet13 Kas 2022
- CVE-2024-3653122İzleyin
nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.
OrtaCVSS 5,7İstismar yokEPSS %0nukeviet · egovernment10 Haz 2024
- CVE-2022-3087421İzleyin
There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02.
OrtaCVSS 5,4İstismar yokEPSS %1nukeviet · nukeviet21 Haz 2022
- CVE-2025-87728İzleyin
Vinades NukeViet Module index.php server-side request forgery
DüşükCVSS 2,1İstismar yokEPSS %0nukeviet · nukeviet9 Ağu 2025